Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2018-15404 Details

Description

A vulnerability in the web interface of Cisco Integrated Management Controller (IMC) Supervisor and Cisco UCS Director could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected system. The vulnerability is due to insufficient restrictions on the size or total amount of resources allowed via the web interface. An attacker who has valid credentials for the application could exploit this vulnerability by sending a crafted or malformed HTTP request to the web interface. A successful exploit could allow the attacker to cause oversubscription of system resources or cause a component to become unresponsive, resulting in a DoS condition.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-770Allocation of Resources Without Limits or Throttling[email protected]
CWE-399Resource Management Errors[email protected]

Affected Products

ProductVersions
cisco unified computing system director
6.6(0.0)

CPE

  • cpe:2.3:a:cisco:unified_computing_system_director:6.6(0.0):*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
cisco integrated management controller supervisor
2.1(0.0)

CPE

  • cpe:2.3:a:cisco:integrated_management_controller_supervisor:2.1(0.0):*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

7 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2018-15404
NVD Published Date:
Oct 5, 2018
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2018-15404 Details - Not Deferred